# What tools do you use to static analysis and to check the code quality?

**URL:** <https://club.ministryoftesting.com/t/what-tools-do-you-use-to-static-analysis-and-to-check-the-code-quality/11922>\
**Category:** Archive\
**Tags:** automation\
**Created:** [29 November 2017 18:32 UTC](https://club.ministryoftesting.com/t/what-tools-do-you-use-to-static-analysis-and-to-check-the-code-quality/11922 "2017-11-29T18:32:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![samuellucas](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/samuellucas/32/2052_2.png) [@samuellucas](https://club.ministryoftesting.com/u/samuellucas)\
**Post date:** [29 November 2017 18:32 UTC](https://club.ministryoftesting.com/t/what-tools-do-you-use-to-static-analysis-and-to-check-the-code-quality/11922/1 "2017-11-29T18:32:55Z")

</div>

What tools and approaches are you using to static analysis and to check the code quality in your development and automation projects?

I’m learning about this subject and I would like to know some use cases.

Also, I found this interesting repository: [https://github.com/mre/awesome-static-analysis](https://github.com/mre/awesome-static-analysis)

Thanks.

---

<div class="post-metadata">

**Author:** ![paulmaxwellwalters](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/paulmaxwellwalters/32/112_2.png) [@paulmaxwellwalters](https://club.ministryoftesting.com/u/paulmaxwellwalters)\
**Post date:** [30 November 2017 23:29 UTC](https://club.ministryoftesting.com/t/what-tools-do-you-use-to-static-analysis-and-to-check-the-code-quality/11922/2 "2017-11-30T23:29:08Z")

</div>

Never used it myself but I had colleagues who swear by Microsoft FX Cop

> **[FxCop](https://en.wikipedia.org/wiki/FxCop)**
>
> FxCop is a free static code analysis tool from Microsoft that checks .NET managed code assemblies for conformance to Microsoft's .NET Framework Design Guidelines. Unlike StyleCop, or the Lint programming tool, for the C programming language, FxCop analyzes the compiled object code, not the original source code. It uses CIL parsing and callgraph analysis to inspect assemblies for more than 200 different possible coding standards violations in the following areas: FxCop includes both GUI and comman...

---

<div class="post-metadata">

**Author:** ![g33klady](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/g33klady/32/734_2.png) [@g33klady](https://club.ministryoftesting.com/u/g33klady)\
**Post date:** [1 December 2017 19:14 UTC](https://club.ministryoftesting.com/t/what-tools-do-you-use-to-static-analysis-and-to-check-the-code-quality/11922/3 "2017-12-01T19:14:01Z")

</div>

We use SonarQube; devs can use the tools built-in to Visual Studio as well.  
As a tester, I look at the analysis and see:

- Where code has changed a lot (churn) -\> prone to bugs
- Where code coverage is lacking -\> help to fix that or find bugs there
- Where “bugs” or “smells” are as identified by the tool
- Where we see cyclomatic complexity and make sure we’ve covered every scenario
- Where code has been duplicated -\> prone to regressions, needs to be consolidated
